What is Data Residency?

Data residency describes where data is physically stored and processed. An organization may need to keep customer records in a particular country or region because of regulation, a customer contract, or internal policy. Data residency is related to, but narrower than, data sovereignty, which concerns which country’s laws govern data, and data localization, which is a legal mandate to keep certain data inside a country.

Residency shapes architecture choices such as which cloud region hosts a database and where backups and logs are kept. It also shapes AI projects. For example, a bank may want to use a model hosted in another region while its customer records must stay in its home region. Teams then decide what leaves the region, in what form, and how results return to the systems where the work happens. Residency rules often sit alongside data privacy requirements.

Frequently asked questions

What is the difference between data residency and data sovereignty?

Data residency is about where data is stored and processed. Data sovereignty is about which jurisdiction's laws apply to that data, which can reach beyond where it physically sits.

Does the GDPR require data residency?

The GDPR does not require personal data to stay inside the EU. It restricts transfers to countries outside the EU unless safeguards such as an adequacy decision or standard contractual clauses apply.

How does data residency affect AI?

It limits where data can be processed, which can rule out some hosted models or require that only certain forms of the data leave the region.